Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Gallery HIGH 7.5
CVE-2008-2722

Menalto Gallery before 2.2.5 allows remote attackers to bypass permissions for sub-albums via a ZIP archive.

Fix: after 2.2.4
Fix from $1,950 2008-06-16
Gallery MEDIUM 5.0
CVE-2008-2724

Menalto Gallery before 2.2.5 does not enforce permissions for non-album items that have been protected by a password, which might allow remote attack…

Mitigation only
Fix from $1,600 2008-06-16
Apache Webserver MEDIUM 6.5
CVE-2008-2717

TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which al…

Mitigation only
Fix from $1,600 2008-06-16
Network Interface Controller HIGH 7.8
CVE-2008-2707

Unspecified vulnerability in the e1000g driver in Sun Solaris 10 and OpenSolaris before snv_93 allows remote attackers to cause a denial of service (…

Mitigation only
Fix from $1,950 2008-06-16
Realm Cms HIGH 7.5
CVE-2008-2682

_RealmAdmin/login.asp in Realm CMS 2.3 and earlier allows remote attackers to bypass authentication and access admin pages via certain modified cooki…

No fix yet
Fix from $1,950 2008-06-12
Instant Messenger HIGH 9.3
CVE-2008-2551EPSS 47%

The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force the download and execution o…

No fix yet
Fix from $1,950 2008-06-04
Pix Security Appliance HIGH 7.8
CVE-2008-2059

Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 8.0.x before 8.0(3)9 allows remote attackers to bypass control-plane ACLs fo…

Mitigation only
Fix from $1,950 2008-06-04
Java Asp Server MEDIUM 5.0
CVE-2008-2402EPSS 11%

The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 stores sensitive information under the web root with insufficient access c…

Fix: after 4.0.2
Fix from $1,600 2008-06-04
Ikiwiki MEDIUM 6.8
CVE-2008-0169

Plugin/passwordauth.pm (aka the passwordauth plugin) in ikiwiki 1.34 through 2.47 allows remote attackers to bypass authentication, and login to any …

Mitigation only
Fix from $1,600 2008-06-03
Cluster HIGH 7.2
CVE-2008-2539

The Sun Cluster Global File System in Sun Cluster 3.1 on Sun Solaris 8 through 10, when an underlying ufs filesystem is used, might allow local users…

Mitigation only
Fix from $1,950 2008-06-03
Safari HIGH 9.3
CVE-2008-2540EPSS 8%

Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, w…

Fix: 3.1.2+
Fix from $1,950 2008-06-03
Aix HIGH 7.2
CVE-2008-2515

Unspecified vulnerability in iostat in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unknown vectors related to an "environment…

Patch available
Fix from $1,950 2008-06-02
Roomphplanning MEDIUM 6.5
CVE-2008-2488

admin/userform.php in RoomPHPlanning 1.5 does not require administrative credentials, which allows remote authenticated users to create new admin acc…

No fix yet
Fix from $1,600 2008-05-28
Stunnel MEDIUM 6.8
CVE-2008-2420

The OCSP functionality in stunnel before 4.24 does not properly search certificate revocation lists (CRL), which allows remote attackers to bypass in…

Patch available
Fix from $1,600 2008-05-23
Stunnel HIGH 7.2
CVE-2008-2400

Unspecified vulnerability in stunnel before 4.23, when running as a service on Windows, allows local users to gain privileges via unknown attack vect…

Mitigation only
Fix from $1,950 2008-05-22
Alkalinephp HIGH 7.5
CVE-2008-2346

AlkalinePHP 0.77.35 and earlier allows remote attackers to bypass authentication and gain administrative access by creating an admin account via a di…

Fix: after 0.77.35
Fix from $1,950 2008-05-20
Meltingice File System HIGH 7.5
CVE-2008-2348

MeltingIce File System 1.0 allows remote attackers to bypass application authentication, create new user accounts, and exceed application quotas via …

No fix yet
Fix from $1,950 2008-05-20
Zomplog HIGH 7.5
CVE-2008-2349

Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direct request to install/newuser.…

Fix: after 3.8.2
Fix from $1,950 2008-05-20
Activekb HIGH 7.5
CVE-2008-2338EPSS 6%

Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when accessing unspecified scripts …

Fix: after 1.5
Fix from $1,950 2008-05-19
News Manager HIGH 7.5
CVE-2008-2343

News Manager 2.0 allows remote attackers to bypass restrictions and obtain sensitive information via a direct request to (1) db/connect_str.php and (…

No fix yet
Fix from $1,950 2008-05-19
Altiris Deployment Solution HIGH 7.2
CVE-2008-2287

Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 does not properly protect the install directory, which might allow local users to…

Patch available
Fix from $1,950 2008-05-18
Altiris Deployment Solution HIGH 7.2
CVE-2008-2289

Unspecified vulnerability in a tooltip element in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows local users to gain priv…

Mitigation only
Fix from $1,950 2008-05-18
Altiris Deployment Solution HIGH 7.2
CVE-2008-2290

Unspecified vulnerability in the Agent user interface in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows local users to ga…

Mitigation only
Fix from $1,950 2008-05-18
Mpcs HIGH 7.5
CVE-2008-2293

admin.php in Multi-Page Comment System (MPCS) 1.0 and 1.1 allows remote attackers to bypass authentication and gain privileges by setting the Comment…

No fix yet
Fix from $1,950 2008-05-18
Pet Grooming Management System HIGH 7.5
CVE-2008-2294

Pet Grooming Management System 2.0 allows remote attackers to gain privileges via a direct request to useradded.php with a modified user name for "ad…

No fix yet
Fix from $1,950 2008-05-18
Rantx HIGH 7.5
CVE-2008-2297

The admin.php file in Rantx allows remote attackers to bypass authentication and gain privileges by setting the logininfo cookie to "<?php" or "?>", …

No fix yet
Fix from $1,950 2008-05-18
Access Essentials MEDIUM 6.5
CVE-2008-2300

Unspecified vulnerability in Citrix Presentation Server 4.5 and earlier, Citrix Access Essentials 2.0 and earlier, and Citrix Desktop Server 1.0 allo…

Fix: after 4.5
Fix from $1,600 2008-05-18
Project Based Calendaring System HIGH 9.0
CVE-2008-2216

Unrestricted file upload vulnerability in src/yopy_upload.php in Project-Based Calendaring System (PBCS) 0.7.1 allows remote authenticated users to u…

No fix yet
Fix from $1,950 2008-05-14
Openkm MEDIUM 5.0
CVE-2008-2226

Unspecified vulnerability in the export feature in OpenKM before 2.0 allows remote attackers to export arbitrary documents via unspecified vectors. …

Fix: after 1.2
Fix from $1,600 2008-05-14
Animal Shelter Manager MEDIUM 6.5
CVE-2008-2174

Multiple unspecified vulnerabilities in Robin Rawson-Tetley Animal Shelter Manager (ASM) before 2.2.2 have unknown impact and attack vectors, related…

Fix: after 2.2.1
Fix from $1,600 2008-05-13